{"id":"302e84db-d316-4243-9e30-4fe0ca3651b5","entityType":"agent","slug":"clawhub-psyb0t-pr0xteus","name":"pr0xteus","canonicalUrl":"https://www.xpersona.co/agent/clawhub-psyb0t-pr0xteus","canonicalPath":"/agent/clawhub-psyb0t-pr0xteus","generatedAt":"2026-10-11T20:57:18.818Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:14:46.726Z","emptyReason":null},"description":"Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pr0xteus","sourceUrl":"https://clawhub.ai/psyb0t/pr0xteus","homepage":"https://clawhub.ai/psyb0t/skills/pr0xteus","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/psyb0t/pr0xteus","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/psyb0t/skills/pr0xteus","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"pr0xteus technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:14:46.726Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:14:46.726Z","emptyReason":null},"stars":null,"forks":null,"downloads":1020,"packageName":null,"latestVersion":"0.11.4","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:14:46.661Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T17:14:46.726Z","lastCrawledAt":"2026-10-11T17:14:46.661Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T17:14:46.661Z","lastVerifiedAt":null,"highlights":[{"version":"0.11.4","createdAt":"2026-09-06T07:07:17.786Z","changelog":"- Removed the file skill-card.md. - No changes to core functionality or usage; documentation and instructions remain unchanged.","fileCount":4,"zipByteSize":8461},{"version":"0.11.1","createdAt":"2026-08-26T03:11:44.925Z","changelog":"pr0xteus 0.11.1 changelog: - Removed obsolete skill-card.md file. - Updated references/setup.md with current setup and usage details. - No user-facing feature or behavioral changes; documentation only.","fileCount":4,"zipByteSize":8309},{"version":"0.11.0","createdAt":"2026-08-26T01:46:15.930Z","changelog":"- Adds support for HTTP proxy endpoints alongside SOCKS5, allowing clients to request both egress types from the same API. - Updates documentation to clarify availability of both SOCKS5 and HTTP proxy URLs, including changes to response shape and usage examples. - Expands relevant sections to mention both proxy protocols and controller-fronted proxy gateways rather than just SOCKS5 exits. - Removes outdated or redundant documentation file (skill-card.md). - Retains all security guidelines and operational boundaries from previous versions.","fileCount":4,"zipByteSize":8332},{"version":"0.10.6","createdAt":"2026-08-21T07:21:29.482Z","changelog":"- Removed the skill-card.md file. - No functional or user-facing changes to the main skill or its documentation.","fileCount":4,"zipByteSize":8279},{"version":"0.10.5","createdAt":"2026-08-21T04:05:26.646Z","changelog":"- Removed the file skill-card.md. - No changes to code or user-facing documentation content. - No new features or fixes introduced in this version.","fileCount":4,"zipByteSize":8241},{"version":"0.10.4","createdAt":"2026-08-21T03:34:41.620Z","changelog":"- Removed the skill-card.md file. - No changes to functionality or documentation content. - No changes to permissions or core logic. - Maintenance update to clean up unused files.","fileCount":4,"zipByteSize":8289},{"version":"0.10.1","createdAt":"2026-08-18T00:55:57.105Z","changelog":"- Removed the skill-card.md file. - No user-facing feature or documentation changes. All instructions and API details remain the same.","fileCount":4,"zipByteSize":8505},{"version":"0.10.0","createdAt":"2026-08-18T00:34:44.510Z","changelog":"- Removed the file: skill-card.md - No changes to functionality or documentation in SKILL.md - No new features or bug fixes - Version 0.10.0 marks a minor cleanup by deleting an unused file","fileCount":4,"zipByteSize":8384}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pr0xteus","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pr0xteus` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/psyb0t/pr0xteus before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T20:57:18.814Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:14:46.726Z","emptyReason":null},"readme":"Skill: pr0xteus\n\nOwner: psyb0t\n\nSummary: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\n\nTags: latest:0.11.4\n\nVersion history:\n\nv0.11.4 | 2026-09-06T07:07:17.786Z | auto\n\n- Removed the file skill-card.md.\n- No changes to core functionality or usage; documentation and instructions remain unchanged.\n\nv0.11.1 | 2026-08-26T03:11:44.925Z | auto\n\npr0xteus 0.11.1 changelog:\n\n- Removed obsolete skill-card.md file.\n- Updated references/setup.md with current setup and usage details.\n- No user-facing feature or behavioral changes; documentation only.\n\nv0.11.0 | 2026-08-26T01:46:15.930Z | auto\n\n- Adds support for HTTP proxy endpoints alongside SOCKS5, allowing clients to request both egress types from the same API.\n- Updates documentation to clarify availability of both SOCKS5 and HTTP proxy URLs, including changes to response shape and usage examples.\n- Expands relevant sections to mention both proxy protocols and controller-fronted proxy gateways rather than just SOCKS5 exits.\n- Removes outdated or redundant documentation file (skill-card.md).\n- Retains all security guidelines and operational boundaries from previous versions.\n\nv0.10.6 | 2026-08-21T07:21:29.482Z | auto\n\n- Removed the skill-card.md file.\n- No functional or user-facing changes to the main skill or its documentation.\n\nv0.10.5 | 2026-08-21T04:05:26.646Z | auto\n\n- Removed the file skill-card.md.\n- No changes to code or user-facing documentation content.\n- No new features or fixes introduced in this version.\n\nv0.10.4 | 2026-08-21T03:34:41.620Z | auto\n\n- Removed the skill-card.md file.\n- No changes to functionality or documentation content.\n- No changes to permissions or core logic.\n- Maintenance update to clean up unused files.\n\nv0.10.1 | 2026-08-18T00:55:57.105Z | auto\n\n- Removed the skill-card.md file.\n- No user-facing feature or documentation changes. All instructions and API details remain the same.\n\nv0.10.0 | 2026-08-18T00:34:44.510Z | auto\n\n- Removed the file: skill-card.md\n- No changes to functionality or documentation in SKILL.md\n- No new features or bug fixes\n- Version 0.10.0 marks a minor cleanup by deleting an unused file\n\nv0.9.7 | 2026-08-17T21:37:35.570Z | auto\n\n- Removed the file: skill-card.md\n- No other functionality or documentation has changed.\n\nv0.9.6 | 2026-08-17T21:03:46.836Z | auto\n\n- Removed the file skill-card.md.\n- No changes to core functionality or APIs.\n- Documentation and usage instructions remain unchanged.\n\nv0.9.5 | 2026-08-17T19:14:58.435Z | auto\n\n- Removed the skill-card.md file.\n- No other changes to functionality or documentation.\n\nv0.9.0 | 2026-08-17T09:56:08.923Z | auto\n\n- Updated setup instructions in references/setup.md.\n- Removed the skill-card.md file.\n- No changes made to core functionality or API behavior.\n\nv0.8.3 | 2026-08-17T02:22:26.948Z | auto\n\n- Removed the pr0xteus skill-card.md file.\n- No changes to functionality or documentation otherwise.\n\nv0.8.2 | 2026-08-17T01:56:36.490Z | auto\n\n- Updated documentation to clarify the new controller-fronted SOCKS5 gateway, replacing direct private cell access.\n- Proxies now return short-lived, controller-mediated SOCKS5 URLs instead of Docker-only endpoints; updated usage and security notes accordingly.\n- Expanded API reference: `/v1/proxies`, `/v1/pools`, and `/v1/cells` now support `limit` and `offset` parameters with collection metadata.\n- Refreshed example `curl` commands to match the changed API and clarify bearer capability usage.\n- Removed outdated skill-card.md; modern setup instructions and usage details are now in SKILL.md and references/setup.md.\n\nv0.5.0 | 2026-08-16T16:29:45.634Z | auto\n\n- Added explicit support and documentation for inspecting live cells (`/v1/cells`) and destroying them on demand.\n- Updated permissions to detail external calls made during preflight checks (api.ipify.org, ifconfig.me) and setup (raw.githubusercontent.com, Docker Hub).\n- Removed outdated file `skill-card.md`.\n- Clarified documentation in SKILL.md regarding new capabilities and safer usage patterns.\n\nv0.4.0 | 2026-08-16T04:22:41.317Z | auto\n\n- Removed the file: skill-card.md.\n- Updated references/setup.md with the latest setup or configuration information. \n- No changes to core functionality or user API. \n- Documentation improvements and minor content cleanup.\n\nv0.3.0 | 2026-08-14T22:12:29.202Z | auto\n\n- Removed the skill-card.md file.\n- No changes to functionality or documentation in SKILL.md.\n- Internal cleanup, removing redundant or autogenerated documentation assets.\n\nv0.2.3 | 2026-08-14T19:48:52.650Z | auto\n\nNo changes detected in this version.\n\n- Version 0.2.3 was released with no updates to any files.\n- Functionality, documentation, and configuration remain unchanged from the previous release.\n\nv0.2.2 | 2026-08-14T18:36:40.543Z | auto\n\n- Added detailed documentation in SKILL.md explaining pr0xteus: a self-hosted WireGuard-backed SOCKS5 exit for trusted workloads.\n- Described key use cases, security policies, and operational boundaries.\n- Provided setup instructions, including environment variable requirements and example API calls.\n- Documented API endpoints for obtaining proxies, inspecting pools, and replacing failed assignments.\n- Included information about safe usage, restrictions, and Go client integration.\n\nArchive index:\n\nArchive v0.11.4: 4 files, 8461 bytes\n\nFiles: references/setup.md (8932b), skill-card.md (2480b), SKILL.md (6346b), _meta.json (128b)\n\nFile v0.11.4:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through allocated SOCKS5 or HTTP URLs exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and\nWireGuard-backed SOCKS5 and HTTP exits. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup, local config, a complete pool example, and proof that a\ncontroller-fronted proxy exit works, read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- Returned `socks5://` and `http://` URLs are short-lived bearer capabilities\n  for the controller's proxy gateways. Keep them out of logs, issue trackers,\n  and public services. Trusted host and container clients can use either; only\n  the controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload configured country-specific SOCKS5 or HTTP egress.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand. See [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `proxies.socks5`, `proxies.http`, `pool`, `exitCountry`,\nand `expiresAt`. Both URLs share one lease and work from the host or another\nreachable trusted client. They authenticate to the controller, which forwards\nto the chosen cell without resolving the destination itself. The setup\nreference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.11.4:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.11.4\",\n  \"publishedAt\": 1788678437786\n}\n\nFile v0.11.4:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives SOCKS5 and HTTP\nproxy URLs only after the controller has started a WireGuard-backed cell and\nconfirmed a handshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example` and managed templates, re-pins to the newest\nrelease, refreshes the command, starts through that command, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nsocks5_proxy=\"$(jq -er '.proxies.socks5' <<<\"$allocation\")\"\nhttp_proxy=\"$(jq -er '.proxies.http' <<<\"$allocation\")\"\n```\n\nThe returned URLs are short-lived credentials for the controller SOCKS5 gateway\nand HTTP proxy. Use either directly from the host; the controller forwards them\nto the selected cell over the internal network, and the cell owns WireGuard\negress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$socks5_proxy\" https://api.ipify.org\n\ncurl --fail --silent --show-error \\\n  --proxy \"$http_proxy\" https://api.ipify.org\n\nunset token socks5_proxy http_proxy allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.11.4:skill-card.md\n\n## Description:\n\nHelps trusted developers and operators use a self-hosted pr0xteus controller to allocate WireGuard-backed SOCKS5 or HTTP egress through a bearer-protected private API.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to give a trusted workload controlled country-specific egress, inspect pools and active cells, replace failed proxy assignments, and integrate a Go client with VPN-only or public-first retry behavior.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The setup path asks users to run a mutable remote installer, with an optional sudo system-wide install path.\n\nMitigation: Download and inspect the installer before execution, prefer immutable releases or commit-pinned downloads, verify checksums or signatures when available, and avoid the sudo path unless system-wide installation is required.\n\nRisk: Proxy URLs and PR0XTEUS_API_TOKEN are bearer credentials that can grant access to private egress capacity.\n\nMitigation: Store tokens in a secret store, keep returned proxy URLs out of logs and public issue trackers, and limit use to trusted clients and operator-approved destinations.\n\nRisk: The controller starts Docker-backed WireGuard cells and can delete active cells on request.\n\nMitigation: Restrict agent and user access to Docker control paths, bind the controller only to loopback or a protected private network, and delete only cells associated with the current authorized task.\n\n## Reference(s):\n\n- [pr0xteus setup](references/setup.md)\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [Project homepage](https://github.com/psyb0t/pr0xteus)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, Code]\n\n**Output Format:** [Markdown with inline bash, curl, Docker, YAML, JSON, and Go-oriented guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses PR0XTEUS_URL and PR0XTEUS_API_TOKEN supplied by the operator; no MCP endpoint is provided.]\n\n## Skill Version(s):\n\n0.11.4 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.1: 4 files, 8309 bytes\n\nFiles: references/setup.md (8932b), skill-card.md (2189b), SKILL.md (6346b), _meta.json (128b)\n\nFile v0.11.1:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through allocated SOCKS5 or HTTP URLs exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and\nWireGuard-backed SOCKS5 and HTTP exits. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup, local config, a complete pool example, and proof that a\ncontroller-fronted proxy exit works, read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- Returned `socks5://` and `http://` URLs are short-lived bearer capabilities\n  for the controller's proxy gateways. Keep them out of logs, issue trackers,\n  and public services. Trusted host and container clients can use either; only\n  the controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload configured country-specific SOCKS5 or HTTP egress.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand. See [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `proxies.socks5`, `proxies.http`, `pool`, `exitCountry`,\nand `expiresAt`. Both URLs share one lease and work from the host or another\nreachable trusted client. They authenticate to the controller, which forwards\nto the chosen cell without resolving the destination itself. The setup\nreference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.11.1:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1787713904925\n}\n\nFile v0.11.1:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives SOCKS5 and HTTP\nproxy URLs only after the controller has started a WireGuard-backed cell and\nconfirmed a handshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example` and managed templates, re-pins to the newest\nrelease, refreshes the command, starts through that command, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nsocks5_proxy=\"$(jq -er '.proxies.socks5' <<<\"$allocation\")\"\nhttp_proxy=\"$(jq -er '.proxies.http' <<<\"$allocation\")\"\n```\n\nThe returned URLs are short-lived credentials for the controller SOCKS5 gateway\nand HTTP proxy. Use either directly from the host; the controller forwards them\nto the selected cell over the internal network, and the cell owns WireGuard\negress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$socks5_proxy\" https://api.ipify.org\n\ncurl --fail --silent --show-error \\\n  --proxy \"$http_proxy\" https://api.ipify.org\n\nunset token socks5_proxy http_proxy allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.11.1:skill-card.md\n\n## Description:\n\npr0xteus guides agents in allocating, inspecting, and safely using trusted WireGuard-backed SOCKS5 and HTTP exits through a private bearer-protected controller.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to set up or talk to a trusted pr0xteus controller, allocate approved country or pool egress, inspect active leases and cells, and replace failed assignments without exposing an open proxy.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Controller tokens and returned proxy URLs can grant access to private egress.\n\nMitigation: Protect PR0XTEUS_API_TOKEN and proxy URLs as credentials, and keep them out of logs, issue trackers, and public services.\n\nRisk: Allocating exits or deleting cells can consume provider capacity or disrupt active egress.\n\nMitigation: Only allocate country or pool exits and delete cells when the user explicitly intends that action.\n\nRisk: Installer and Docker setup affect local configuration, containers, and WireGuard-backed routing.\n\nMitigation: Review the downloaded installer before running it and install only for a pr0xteus controller you operate and trust.\n\n## Reference(s):\n\n- [pr0xteus setup](artifact/references/setup.md)\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [Project homepage](https://github.com/psyb0t/pr0xteus)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration, API calls]\n\n**Output Format:** [Markdown with inline bash, JSON, and YAML snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires a trusted pr0xteus controller and user-provided PR0XTEUS_URL and PR0XTEUS_API_TOKEN; no MCP tools are provided.]\n\n## Skill Version(s):\n\n0.11.1 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.0: 4 files, 8332 bytes\n\nFiles: references/setup.md (8858b), skill-card.md (2374b), SKILL.md (6346b), _meta.json (128b)\n\nFile v0.11.0:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through allocated SOCKS5 or HTTP URLs exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and\nWireGuard-backed SOCKS5 and HTTP exits. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup, local config, a complete pool example, and proof that a\ncontroller-fronted proxy exit works, read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- Returned `socks5://` and `http://` URLs are short-lived bearer capabilities\n  for the controller's proxy gateways. Keep them out of logs, issue trackers,\n  and public services. Trusted host and container clients can use either; only\n  the controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload configured country-specific SOCKS5 or HTTP egress.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand. See [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `proxies.socks5`, `proxies.http`, `pool`, `exitCountry`,\nand `expiresAt`. Both URLs share one lease and work from the host or another\nreachable trusted client. They authenticate to the controller, which forwards\nto the chosen cell without resolving the destination itself. The setup\nreference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.11.0:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.11.0\",\n  \"publishedAt\": 1787708775930\n}\n\nFile v0.11.0:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives SOCKS5 and HTTP\nproxy URLs only after the controller has started a WireGuard-backed cell and\nconfirmed a handshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example`, re-pins to the newest release, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nsocks5_proxy=\"$(jq -er '.proxies.socks5' <<<\"$allocation\")\"\nhttp_proxy=\"$(jq -er '.proxies.http' <<<\"$allocation\")\"\n```\n\nThe returned URLs are short-lived credentials for the controller SOCKS5 gateway\nand HTTP proxy. Use either directly from the host; the controller forwards them\nto the selected cell over the internal network, and the cell owns WireGuard\negress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$socks5_proxy\" https://api.ipify.org\n\ncurl --fail --silent --show-error \\\n  --proxy \"$http_proxy\" https://api.ipify.org\n\nunset token socks5_proxy http_proxy allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.11.0:skill-card.md\n\n## Description:\n\npr0xteus guides agents in allocating and operating trusted WireGuard-backed SOCKS5 and HTTP proxy exits through a bearer-protected private controller.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to give trusted self-hosted workloads controlled country-specific or pool-specific egress, inspect proxy and cell state, replace failed assignments, and follow guarded setup steps for a private pr0xteus deployment.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Bearer tokens and returned proxy URLs can grant access to the private controller or proxy gateways.\n\nMitigation: Use only user-provided PR0XTEUS_URL and PR0XTEUS_API_TOKEN values from the environment or a secret store, and keep returned proxy URLs out of logs, issue trackers, and public services.\n\nRisk: Allocating or destroying cells can consume provider capacity or disrupt operator-managed egress.\n\nMitigation: Request only the country, pool, and task the user approved; use excludeProxy for replacement; destroy only cells the user allocated or is authorized to manage.\n\nRisk: Installer and Docker setup steps affect local configuration, containers, and WireGuard-backed routing.\n\nMitigation: Review the installer before running it, pin released images for normal operation, and use only operator-owned configuration paths and authorized WireGuard bundles.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [pr0xteus setup](references/setup.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with bash, curl, Docker, JSON, and YAML snippets]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include private controller API calls and setup commands that require user-provided PR0XTEUS_URL and PR0XTEUS_API_TOKEN values]\n\n## Skill Version(s):\n\n0.11.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.6: 4 files, 8279 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2409b), SKILL.md (6294b), _meta.json (128b)\n\nFile v0.10.6:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API. Request an operator-approved ISO country or logical pool, inspect current leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and a controller-fronted SOCKS5 gateway. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through an allocated SOCKS5 URL exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and a\nWireGuard-backed SOCKS5 exit. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup — local config, a complete pool example, and proof that a\ncontroller-fronted SOCKS5 exit works — read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- A returned `socks5://` URL is a short-lived bearer capability for the\n  controller's SOCKS gateway. Keep it out of logs, issue trackers, and public\n  services. Trusted host and container clients can use it directly; only the\n  controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload a configured country-specific SOCKS5 exit.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken SOCKS5 assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand — see [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `url`, `pool`, `exitCountry`, and `expiresAt`. The URL\nworks from the host or another reachable trusted client: it authenticates to\nthe controller, which forwards to the chosen cell without resolving the\ndestination itself. The setup reference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.10.6:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.10.6\",\n  \"publishedAt\": 1787296889482\n}\n\nFile v0.10.6:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives a SOCKS5 URL\nonly after the controller has started a WireGuard-backed cell and seen a\nhandshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example`, re-pins to the newest release, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nproxy_url=\"$(jq -er '.url' <<<\"$allocation\")\"\n```\n\nThe returned URL is a short-lived credential for the controller SOCKS gateway.\nUse it directly from the host; the controller forwards it to the selected cell\nover the internal network and the cell owns WireGuard egress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$proxy_url\" https://api.ipify.org\n\nunset token proxy_url allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.10.6:skill-card.md\n\n## Description:\n\npr0xteus guides agents through operating a trusted private controller that allocates WireGuard-backed SOCKS5 exits, inspects pools and cells, replaces failed assignments, and integrates Go clients without exposing an open proxy.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to connect trusted self-hosted workloads to operator-approved country or pool exits through a private pr0xteus control API. It helps them check health and pool state, allocate or replace SOCKS5 assignments, inspect live cells, and follow the documented Docker-backed setup path.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can guide allocation of proxy capacity and route traffic through operator-controlled WireGuard exits.\n\nMitigation: Use only trusted private controllers and request only operator-approved countries, pools, and destinations.\n\nRisk: Bearer tokens and returned SOCKS5 URLs can grant access to the control API or gateway if exposed.\n\nMitigation: Keep PR0XTEUS_API_TOKEN and returned proxy URLs out of logs, tickets, public services, and generated artifacts.\n\nRisk: Setup and cell operations can start Docker-backed infrastructure or stop active pr0xteus cells.\n\nMitigation: Inspect the installer before running it and require explicit user intent before teardown actions.\n\n## Reference(s):\n\n- [pr0xteus ClawHub page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [pr0xteus homepage](https://github.com/psyb0t/pr0xteus)\n- [pr0xteus setup](artifact/references/setup.md)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Shell commands, Configuration, Code, Guidance]\n\n**Output Format:** [Markdown with inline bash, JSON, YAML, and Go-oriented guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses PR0XTEUS_URL and PR0XTEUS_API_TOKEN supplied by the operator; returned SOCKS5 URLs should be treated as short-lived bearer credentials.]\n\n## Skill Version(s):\n\n0.10.6 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.5: 4 files, 8241 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2316b), SKILL.md (6294b), _meta.json (128b)\n\nFile v0.10.5:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API. Request an operator-approved ISO country or logical pool, inspect current leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and a controller-fronted SOCKS5 gateway. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through an allocated SOCKS5 URL exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and a\nWireGuard-backed SOCKS5 exit. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup — local config, a complete pool example, and proof that a\ncontroller-fronted SOCKS5 exit works — read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- A returned `socks5://` URL is a short-lived bearer capability for the\n  controller's SOCKS gateway. Keep it out of logs, issue trackers, and public\n  services. Trusted host and container clients can use it directly; only the\n  controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload a configured country-specific SOCKS5 exit.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken SOCKS5 assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand — see [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `url`, `pool`, `exitCountry`, and `expiresAt`. The URL\nworks from the host or another reachable trusted client: it authenticates to\nthe controller, which forwards to the chosen cell without resolving the\ndestination itself. The setup reference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.10.5:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.10.5\",\n  \"publishedAt\": 1787285126646\n}\n\nFile v0.10.5:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives a SOCKS5 URL\nonly after the controller has started a WireGuard-backed cell and seen a\nhandshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example`, re-pins to the newest release, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nproxy_url=\"$(jq -er '.url' <<<\"$allocation\")\"\n```\n\nThe returned URL is a short-lived credential for the controller SOCKS gateway.\nUse it directly from the host; the controller forwards it to the selected cell\nover the internal network and the cell owns WireGuard egress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$proxy_url\" https://api.ipify.org\n\nunset token proxy_url allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.10.5:skill-card.md\n\n## Description:\n\nGive a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to configure, allocate, inspect, and replace private pr0xteus SOCKS5 exits for trusted workloads that need operator-approved country or pool routing.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Bearer tokens and returned SOCKS5 URLs can grant access to private proxy control or egress capabilities if exposed.\n\nMitigation: Read PR0XTEUS_API_TOKEN from approved secret storage, keep allocated SOCKS5 URLs out of logs and public systems, and clear temporary shell variables after use.\n\nRisk: Proxy allocation can consume provider capacity and route traffic through operator-owned WireGuard exits.\n\nMitigation: Request only user-approved countries, pools, and destinations, and avoid public or anonymous proxy use cases.\n\nRisk: Setup and lifecycle commands can start Docker containers, pull images, write local configuration, or delete live cells.\n\nMitigation: Inspect installers before execution, use pinned releases for normal operation, and delete only cells the task allocated or the user explicitly approved.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [pr0xteus setup](references/setup.md)\n- [pr0xteus homepage](https://github.com/psyb0t/pr0xteus)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include bearer-token API call examples, SOCKS5 proxy allocation guidance, Docker setup commands, and configuration snippets.]\n\n## Skill Version(s):\n\n0.10.5 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.4: 4 files, 8289 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2457b), SKILL.md (6294b), _meta.json (128b)\n\nFile v0.10.4:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API. Request an operator-approved ISO country or logical pool, inspect current leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and a controller-fronted SOCKS5 gateway. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through an allocated SOCKS5 URL exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and a\nWireGuard-backed SOCKS5 exit. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup — local config, a complete pool example, and proof that a\ncontroller-fronted SOCKS5 exit works — read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- A returned `socks5://` URL is a short-lived bearer capability for the\n  controller's SOCKS gateway. Keep it out of logs, issue trackers, and public\n  services. Trusted host and container clients can use it directly; only the\n  controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload a configured country-specific SOCKS5 exit.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken SOCKS5 assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand — see [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `url`, `pool`, `exitCountry`, and `expiresAt`. The URL\nworks from the host or another reachable trusted client: it authenticates to\nthe controller, which forwards to the chosen cell without resolving the\ndestination itself. The setup reference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.10.4:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.10.4\",\n  \"publishedAt\": 1787283281620\n}\n\nFile v0.10.4:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives a SOCKS5 URL\nonly after the controller has started a WireGuard-backed cell and seen a\nhandshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example`, re-pins to the newest release, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nproxy_url=\"$(jq -er '.url' <<<\"$allocation\")\"\n```\n\nThe returned URL is a short-lived credential for the controller SOCKS gateway.\nUse it directly from the host; the controller forwards it to the selected cell\nover the internal network and the cell owns WireGuard egress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$proxy_url\" https://api.ipify.org\n\nunset token proxy_url allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.10.4:skill-card.md\n\n## Description:\n\npr0xteus helps agents guide trusted self-hosted workloads through a bearer-protected private API to allocate and inspect operator-approved WireGuard-backed SOCKS5 exits.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to configure, allocate, inspect, replace, and tear down private country-specific SOCKS5 exits backed by operator-managed WireGuard cells. It is intended for trusted workloads and protected controller endpoints, not public proxy service operation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can guide Docker-based controller setup and proxy allocation that affect operator infrastructure and provider capacity.\n\nMitigation: Use it only with a controller you operate and trust, prefer per-user setup unless system-wide operation is required, and request only operator-approved countries, pools, and teardown actions.\n\nRisk: Bearer tokens and returned SOCKS5 URLs are sensitive capabilities for the private controller and gateway.\n\nMitigation: Read tokens from the environment or a secret store, keep returned proxy URLs out of logs and public channels, and unset temporary shell variables after use.\n\nRisk: The setup flow may download an installer and start containers.\n\nMitigation: Inspect the downloaded installer before running it and use pinned release images unless the operator explicitly chooses rolling images.\n\n## Reference(s):\n\n- [pr0xteus setup](references/setup.md)\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [Publisher profile](https://clawhub.ai/user/psyb0t)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, Code]\n\n**Output Format:** [Markdown with inline bash, JSON, YAML, and Go-oriented guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include private controller API calls and setup checks; returned SOCKS5 URLs and bearer tokens should be kept out of logs and public channels.]\n\n## Skill Version(s):\n\n0.10.4 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.1: 4 files, 8505 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2904b), SKILL.md (6294b), _meta.json (128b)\n\nFile v0.10.1:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API. Request an operator-approved ISO country or logical pool, inspect current leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and a controller-fronted SOCKS5 gateway. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through an allocated SOCKS5 URL exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and a\nWireGuard-backed SOCKS5 exit. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup — local config, a complete pool example, and proof that a\ncontroller-fronted SOCKS5 exit works — read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- A returned `socks5://` URL is a short-lived bearer capability for the\n  controller's SOCKS gateway. Keep it out of logs, issue trackers, and public\n  services. Trusted host and container clients can use it directly; only the\n  controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload a configured country-specific SOCKS5 exit.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken SOCKS5 assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand — see [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `url`, `pool`, `exitCountry`, and `expiresAt`. The URL\nworks from the host or another reachable trusted client: it authenticates to\nthe controller, which forwards to the chosen cell without resolving the\ndestination itself. The setup reference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.10.1:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.10.1\",\n  \"publishedAt\": 1787014557105\n}\n\nFile v0.10.1:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives a SOCKS5 URL\nonly after the controller has started a WireGuard-backed cell and seen a\nhandshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example`, re-pins to the newest release, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nproxy_url=\"$(jq -er '.url' <<<\"$allocation\")\"\n```\n\nThe returned URL is a short-lived credential for the controller SOCKS gateway.\nUse it directly from the host; the controller forwards it to the selected cell\nover the internal network and the cell owns WireGuard egress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$proxy_url\" https://api.ipify.org\n\nunset token proxy_url allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.10.1:skill-card.md\n\n## Description:\n\npr0xteus helps trusted self-hosted workloads request and operate operator-approved WireGuard-backed SOCKS5 exits through a private bearer-protected controller, including pool inspection, assignment replacement, and Go-client integration.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to give trusted services controlled, country-specific SOCKS5 egress through an operator-owned pr0xteus controller without exposing an open proxy. It is also used to inspect pools and cells, replace failed assignments, and follow documented setup or Go-client integration paths.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Control tokens and returned SOCKS5 URLs are bearer capabilities that could grant access if exposed.\n\nMitigation: Read tokens from trusted environment or secret storage, keep PR0XTEUS_API_TOKEN and SOCKS5 URLs out of logs and public artifacts, and unset temporary shell variables after use.\n\nRisk: Allocating or deleting cells can consume provider capacity or disrupt the task's active egress path.\n\nMitigation: Request only operator-approved countries or pools for the user-named task, and delete only cells associated with user-requested cleanup for that allocation.\n\nRisk: Setup commands download an installer and run Docker operations that affect local networking and configuration.\n\nMitigation: Inspect the downloaded installer before execution, use trusted private controller endpoints, pin released images unless explicitly using rolling behavior, and keep controller access protected.\n\nRisk: Misconfiguration could turn private egress plumbing into an exposed proxy surface.\n\nMitigation: Keep the controller on loopback or another protected bind address, use operator-owned WireGuard material, and avoid untrusted callers or unapproved destinations.\n\n## Reference(s):\n\n- [pr0xteus setup](references/setup.md)\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [Project homepage](https://github.com/psyb0t/pr0xteus)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, shell commands, configuration, code]\n\n**Output Format:** [Markdown guidance with bash, curl, Docker, jq, YAML, and Go-client examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [The skill provides operator-facing instructions and request examples; it does not expose an MCP endpoint or execute controller operations by itself.]\n\n## Skill Version(s):\n\n0.10.1 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.10.0: 4 files, 8384 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2653b), SKILL.md (6294b), _meta.json (128b)\n\nFile v0.10.0:SKILL.md\n\n---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API. Request an operator-approved ISO country or logical pool, inspect current leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and a controller-fronted SOCKS5 gateway. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through an allocated SOCKS5 URL exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and a\nWireGuard-backed SOCKS5 exit. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup — local config, a complete pool example, and proof that a\ncontroller-fronted SOCKS5 exit works — read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- A returned `socks5://` URL is a short-lived bearer capability for the\n  controller's SOCKS gateway. Keep it out of logs, issue trackers, and public\n  services. Trusted host and container clients can use it directly; only the\n  controller talks to the selected cell's private address.\n- pr0xteus has no MCP endpoint. This is a documentation skill, not a fake\n  bridge plugin with invented tools.\n\n## Use it for\n\n- Giving a trusted workload a configured country-specific SOCKS5 exit.\n- Checking whether the controller is alive or inspecting configured pools and\n  their hot-tunnel state.\n- Replacing a broken SOCKS5 assignment while avoiding the same old cell.\n- Inspecting live cells and their traffic (`/v1/cells`), or destroying one on\n  demand — see [references/setup.md](references/setup.md#cells).\n- Wiring a Go service through `pkg/client`, with VPN-only traffic by default or\n  explicit public-first fallback where that makes sense.\n\n## Do not use it for\n\n- A public or anonymous proxy service.\n- Provider-account provisioning, config scraping, or random WireGuard surgery\n  outside the operator-owned pool policy.\n- An untrusted caller, public proxy use case, or a destination the operator\n  has not approved.\n\n## Talk to a running controller\n\nSet the private control URL and bearer token supplied by the operator:\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n```\n\nHealth lives on the separate metrics listener and deliberately has no token:\n\n```bash\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\nAsk for the configured US route:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nThe response contains `url`, `pool`, `exitCountry`, and `expiresAt`. The URL\nworks from the host or another reachable trusted client: it authenticates to\nthe controller, which forwards to the chosen cell without resolving the\ndestination itself. The setup reference shows a direct `curl --proxy` proof.\n\nInspect active exits without creating another lease:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  \"$PR0XTEUS_URL/v1/proxies?limit=100\" | jq .\n```\n\nEvery collection route (`/v1/proxies`, `/v1/pools`, and `/v1/cells`) accepts\n`limit` and `offset` and returns its items plus `limit`, `offset`, and `total`.\n\nInspect the operator view:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\n```\n\n## Replace a bad assignment\n\nThere is no lease-release endpoint. pr0xteus records the assignment, finishes\nthe API request, then keeps a healthy cell warm until its idle policy reaps it.\nIf the workload cannot use an allocated proxy, request another one and exclude\nthe old URL:\n\n```bash\ncurl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\",\"excludeProxy\":\"socks5://previous-lease-id:previous-secret@127.0.0.1:1080\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\n## Go client\n\nThe public [`pkg/client`](../../../pkg/client) package requests a proxy,\nbuilds an HTTP client around it, and can preflight that the exit IP changes.\nKeep the control token in the service's secret store and pass it with\n`client.WithBearerToken`; the package doc comment contains the full shape.\n\nRead [references/setup.md](references/setup.md) before changing local pool\npolicy or operating the persistent stack.\n\nFile v0.10.0:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.10.0\",\n  \"publishedAt\": 1787013284510\n}\n\nFile v0.10.0:references/setup.md\n\n# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives a SOCKS5 URL\nonly after the controller has started a WireGuard-backed cell and seen a\nhandshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart the image-first deployment:\n\n```bash\npr0xteus start\ncurl --fail --silent http://127.0.0.1:9091/healthz\n```\n\n`pr0xteus start` checks the local token, WireGuard bundle, pools, and routing\nbefore it starts containers. `latest` carries `cell-latest`; a versioned controller carries its matching\nversioned cell. The controller pulls that cell on demand; its image is not an\noperator setting.\n\nThe installer pins to the latest tagged release, not `:latest`. Lifecycle\ncommands: `pr0xteus stop`, `pr0xteus restart`,\n`pr0xteus status`, `pr0xteus logs`, `pr0xteus upgrade`\n(refreshes `.env.example`, re-pins to the newest release, and drops the old\nimage), and `pr0xteus uninstall` (prompts before deleting\n`~/.config/pr0xteus`). Append `--rolling` to `start`/`upgrade` to use the moving\n`:latest` image for one run.\n\nTo reach the controller from a tailnet without binding controller ports on the\nhost, set `PR0XTEUS_TAILSCALE_ENABLED=true` and\n`PR0XTEUS_DISABLE_HOST_PORTS=true`; see the sidecar option in\n[docs/deploy.md](../../../../docs/deploy.md#tailscale-sidecar).\n\n## Run it with Docker directly\n\nThe `pr0xteus` command is only a guardrail around Docker: it pulls the pinned\nimage, runs the image's `config init`, and drives `docker compose`. To do it\nyourself against a config directory you own — no installer, no wrapper — pin a\nreleased tag (not `:latest`) and reproduce those steps:\n\n```bash\nconfig_dir=~/.config/pr0xteus            # any directory you own\nimage=psyb0t/pr0xteus:vX.Y.Z             # pin a released tag\nmkdir -p \"$config_dir\"\ndocker pull \"$image\"\n\n# Scaffold compose + .env + config skeleton and refresh .env.example (.env stays untouched).\ndocker run --rm --user \"$(id -u):$(id -g)\" \\\n  -v \"$config_dir:/config\" \\\n  \"$image\" config init \\\n  --config-dir /config \\\n  --host-config-dir \"$config_dir\" \\\n  --controller-image \"$image\"\n\n# Fill secrets/wireguard/*.conf, secrets/pools.yaml, config/egress-routing.yaml,\n# and PR0XTEUS_API_TOKEN in .env (see above), then bring the stack up:\ndocker compose --project-directory \"$config_dir\" \\\n  --env-file \"$config_dir/.env\" \\\n  -f \"$config_dir/docker-compose.yml\" \\\n  -f \"$config_dir/docker-compose.host-ports.yml\" up -d\n```\n\nIf `.env` sets `PR0XTEUS_DISABLE_HOST_PORTS=true`, add\n`-f \"$config_dir/docker-compose.no-host-ports.yml\"` after the base Compose\nfile *instead of* `docker-compose.host-ports.yml`. The wrapper does this\nautomatically.\n\n`--host-config-dir` must be the real host path so the controller can bind one\nchosen WireGuard file into a cell. This is exactly what `pr0xteus setup` +\n`pr0xteus start` do for you.\n\n## Allocate and prove a proxy\n\n```bash\ntoken=\"$(sed -n 's/^PR0XTEUS_API_TOKEN=//p' ~/.config/pr0xteus/.env)\"\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$token\"))\n\nallocation=\"$(\n  curl --fail-with-body --request POST \\\n    \"${auth_header[@]}\" \\\n    --header 'Content-Type: application/json' \\\n    --data '{\"country\":\"US\"}' \\\n    http://127.0.0.1:8000/v1/proxies\n)\"\nproxy_url=\"$(jq -er '.url' <<<\"$allocation\")\"\n```\n\nThe returned URL is a short-lived credential for the controller SOCKS gateway.\nUse it directly from the host; the controller forwards it to the selected cell\nover the internal network and the cell owns WireGuard egress. To inspect active\nexits without making another allocation:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \\\n  'http://127.0.0.1:8000/v1/proxies?limit=100' | jq .\n```\n\nUse the allocated URL for real traffic:\n\n```bash\ncurl --fail --silent --show-error \\\n  --proxy \"$proxy_url\" https://api.ipify.org\n\nunset token proxy_url allocation\nunset -a auth_header\n```\n\n## Cells\n\nThe controller also exposes the live cell state behind the pools above —\nobservability plus on-demand teardown, discovered straight from Docker (the\n`pr0xteus.parent.id` label), not from in-memory bookkeeping:\n\n```bash\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells\" | jq .\n\n# containerID is a \"containerId\" value from the list above.\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\" | jq .\n```\n\nEach cell view carries `containerId`, `parentId`, `pool`, `confName`, `state`\n(Docker's own container state), `exitCountry`, `createdAt`, `uptimeSeconds`,\nand a `traffic` snapshot (`requests`, `bytesUp`, `bytesDown`, `active`,\n`dialFailures`, `destinations`) scraped from the cell's own `/status`.\n`traffic` is omitted and `statusError` set when the controller can't reach a\ncell's control server. `GET /v1/cells/{containerID}` 404s when the ID isn't\ntracked.\n\n`DELETE /v1/cells/{containerID}` stops that cell's container and clears its\npool slot so the next request re-spawns; `204` on success, `404` when\nuntracked. Only destroy a cell your own task allocated, and only when the\nuser asked for it.\n\n```bash\ncurl --fail-with-body --request DELETE \\\n  \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/cells/$containerID\"\n```\n\n## Agent API use\n\nUse the private controller URL and bearer token supplied through the plugin's\nsensitive configuration. Do not read the operator's `.env`, WireGuard files,\nor Docker socket.\n\n```bash\nexport PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=read-it-from-your-secret-store\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))\n\ncurl --fail-with-body \"${auth_header[@]}\" \"$PR0XTEUS_URL/v1/pools\" | jq .\ncurl --fail-with-body --request POST \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"pool\":\"us\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\"\n```\n\nFor a broken allocation, ask for a replacement with `excludeProxy`. Do not\nlook for a release endpoint: assignment tracking is not a proxy-session lease.\n\nFile v0.10.0:skill-card.md\n\n## Description:\n\nGive a trusted self-hosted workload a configured WireGuard-backed SOCKS5 exit through pr0xteus's bearer-protected private HTTP API.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to configure and operate a trusted private pr0xteus controller for country-specific SOCKS5 egress. It helps allocate approved exits, inspect pools and live cells, replace failed assignments, and integrate a Go client without exposing an open proxy.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Using an untrusted pr0xteus controller or destination can route workload traffic through infrastructure the operator did not approve.\n\nMitigation: Install and use the skill only with a pr0xteus instance the user operates or explicitly trusts, and request only operator-approved countries, pools, and destinations.\n\nRisk: PR0XTEUS_API_TOKEN values and returned SOCKS5 URLs are bearer credentials that can grant access to the private controller or a short-lived exit.\n\nMitigation: Keep tokens and SOCKS5 URLs out of logs, issue trackers, public services, and generated output unless the user explicitly asks to inspect them.\n\nRisk: Proxy allocation and cell deletion can consume provider capacity or disrupt active egress.\n\nMitigation: Allocate exits, exclude prior proxies, or delete cells only when the user has clearly requested that operational action.\n\nRisk: Setup uses shell, Docker, a \n\nArchive v0.9.7: 4 files, 8488 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2888b), SKILL.md (6294b), _meta.json (127b)\n\nArchive v0.9.6: 4 files, 8323 bytes\n\nFiles: references/setup.md (8645b), skill-card.md (2478b), SKILL.md (6294b), _meta.json (127b)","readmeExcerpt":"Skill: pr0xteus Owner: psyb0t Summary: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles,","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"export PR0XTEUS_URL=http://127.0.0.1:8000\nexport PR0XTEUS_API_TOKEN=replace-with-the-token-from-your-secret-store\n\nauth_header=(--header @<(printf 'Authorization: Bearer %s' \"$PR0XTEUS_API_TOKEN\"))"},{"language":"bash","snippet":"curl --fail --silent http://127.0.0.1:9091/healthz"},{"language":"bash","snippet":"curl --fail --silent http://127.0.0.1:9091/healthz"},{"language":"bash","snippet":"curl --fail-with-body --request POST \\"},{"language":"bash","snippet":"curl --fail-with-body --request POST \\\n  \"${auth_header[@]}\" \\\n  --header 'Content-Type: application/json' \\\n  --data '{\"country\":\"US\"}' \\\n  \"$PR0XTEUS_URL/v1/proxies\""},{"language":"bash","snippet":"curl --fail-with-body \"${auth_header[@]}\" \\"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: pr0xteus\ndescription: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.\nhomepage: https://github.com/psyb0t/pr0xteus\nuser-invocable: true\nmetadata:\n  openclaw:\n    emoji: \"🧬\"\n    primaryEnv: PR0XTEUS_URL\n    requires:\n      bins: [bash, curl, docker, jq]\npermissions:\n  network: \"Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through allocated SOCKS5 or HTTP URLs exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image.\"\n  shell: \"bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification.\"\n  filesystem: \"Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files.\"\n---\n\n# pr0xteus\n\npr0xteus is the not-an-open-proxy bit between a trusted service and\nWireGuard-backed SOCKS5 and HTTP exits. The operator owns the local pool policy. Callers\ncan ask for an approved country or pool; they cannot smuggle Docker flags,\nhost paths, images, or arbitrary provider configs into the daemon.\n\nFor the actual setup, local config, a complete pool example, and proof that a\ncontroller-fronted proxy exit works, read\n[references/setup.md](references/setup.md) before touching the stack.\n\n## Security and safety\n\n- This skill is for an instance the user already runs and trusts. Do not hunt\n  through the workspace for tokens, provider bundles, or Docker config. Take\n  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.\n- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend\n  provider capacity and sends later traffic through the operator's exit, so\n  only request the country, pool, and task the user actually named.\n- Returned `socks5://` and `http://` URLs are short-lived bearer capabilities\n  for the controller's proxy gateways. Keep them out of logs, issue trackers,\n  and public services. Trusted host and container clients can use either; only\n  the controller talks to the selected cell's private address.\n- pr0xteu"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"pr0xteus\",\n  \"version\": \"0.11.4\",\n  \"publishedAt\": 1788678437786\n}"},{"path":"references/setup.md","content":"# pr0xteus setup\n\nPr0xteus is private egress plumbing. A trusted client receives SOCKS5 and HTTP\nproxy URLs only after the controller has started a WireGuard-backed cell and\nconfirmed a handshake. It is not an internet-facing proxy. Keep the controller on loopback,\nremove host bindings for an authenticated private-network gateway, or\ndeliberately configure another protected bind address. Use WireGuard material\nyou are allowed to use.\n\nFor the full operator walkthrough, see\n[docs/complete-example.md](../../../../docs/complete-example.md). This page is\nthe agent fast path: use the published image and its installer; do not invent\npaths, tokens, or Docker flags.\n\n## Operator setup\n\n**Download the installer and read it before running it — never pipe `curl`\nstraight into a shell.** Confirm it only fetches the pinned image, runs the\nimage's `config init`, and installs the `pr0xteus` command — then run it.\n\n```bash\n# 1. Download (do not pipe curl into a shell).\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh\n\n# 2. Inspect — read the whole thing.\nless pr0xteus-install.sh\n\n# 3a. Per-user install (no root): command -> ~/.local/bin, config ->\n#     ~/.config/pr0xteus, just for the current user.\nbash pr0xteus-install.sh\n\n# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus\n#     (root-owned, readable by the `docker` group so any docker-group operator\n#     drives the one shared stack).\nsudo bash pr0xteus-install.sh --system\n```\n\nThe mode auto-detects from who runs it (root → system-wide, otherwise\nper-user); force it with `--user` or `--system`. Append `--rolling` to pin the\nmoving `:latest` instead of the latest release. A per-user install that finds\n`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.\n\nThe installer creates ignored local files only when absent (per-user paths\nshown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):\n\n```text\n~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files\n~/.config/pr0xteus/secrets/pools.yaml            approved logical pools\n~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy\n~/.config/pr0xteus/.env                           bearer token, host path, image and ports\n~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect\n```\n\nThe bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate\nsecret file. The installer owns the absolute host path the controller needs\nwhen it asks Docker to bind one chosen file into a cell.\n\nPut an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make\nthe policy match its basename. A file named `us-example.conf` uses `us-example`\nbelow:\n\n```yaml\npools:\n  us:\n    region: north-america\n    purpose: private-service-egress\n    configs: [us-example]\n    exit_countries:\n      us-example: US\n```\n\n```yaml\ncountry_to_pool:\n  US: us\ndefault_pool: us\n```\n\nStart t"},{"path":"skill-card.md","content":"## Description:\n\nHelps trusted developers and operators use a self-hosted pr0xteus controller to allocate WireGuard-backed SOCKS5 or HTTP egress through a bearer-protected private API.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to give a trusted workload controlled country-specific egress, inspect pools and active cells, replace failed proxy assignments, and integrate a Go client with VPN-only or public-first retry behavior.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The setup path asks users to run a mutable remote installer, with an optional sudo system-wide install path.\n\nMitigation: Download and inspect the installer before execution, prefer immutable releases or commit-pinned downloads, verify checksums or signatures when available, and avoid the sudo path unless system-wide installation is required.\n\nRisk: Proxy URLs and PR0XTEUS_API_TOKEN are bearer credentials that can grant access to private egress capacity.\n\nMitigation: Store tokens in a secret store, keep returned proxy URLs out of logs and public issue trackers, and limit use to trusted clients and operator-approved destinations.\n\nRisk: The controller starts Docker-backed WireGuard cells and can delete active cells on request.\n\nMitigation: Restrict agent and user access to Docker control paths, bind the controller only to loopback or a protected private network, and delete only cells associated with the current authorized task.\n\n## Reference(s):\n\n- [pr0xteus setup](references/setup.md)\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)\n- [Project homepage](https://github.com/psyb0t/pr0xteus)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, Code]\n\n**Output Format:** [Markdown with inline bash, curl, Docker, YAML, JSON, and Go-oriented guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses PR0XTEUS_URL and PR0XTEUS_API_TOKEN supplied by the operator; no MCP endpoint is provided.]\n\n## Skill Version(s):\n\n0.11.4 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1729,"uniquenessScore":42,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T17:14:46.726Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T17:14:46.726Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T20:57:18.818Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}